Oracle Glitch Hands MEV Bot $7.5M at Rho Markets — Then It All Comes Back
A faulty price feed at Rho Markets briefly cost the Scroll-based lending protocol $7.5 million on July 19, 2024, before a self-described MEV operator quietly handed the entire sum back.
Rho Markets is built as a fork of Compound Finance, and per DeFiLlama was holding roughly $38 million in deposits just before the incident. Compound's own codebase had already been in the headlines the week prior, after a string of front-end hijacks hit several DeFi sites, as reported by Protos.

The trouble at Rho traced back to a misconfigured oracle. Bad price data opened up an arbitrage window that a watching bot moved on almost immediately, extracting $7.5 million from the protocol within minutes.
On-chain researcher CJ the "Doughnut" was first to flag the activity, noting that the protocol's USDC and USDT reserves had been drained. CJ also surfaced the wallet believed to belong to the actor — 0xe000008459b74a91e306a47c808061dfa372000e — which showed roughly $7.5 million in gains accumulated over the preceding hours.
Rho Markets moved quickly, acknowledging the abnormal activity and pausing the platform. Scroll, the Layer 2 network the protocol runs on, went a step further and briefly halted the entire chain in response.
Investigator ZachXBT weighed in early, pointing out that the exploiter's wallet had significant links to centralized exchanges — a pattern he said made a friendly resolution plausible, floating the possibility of a grey- or white-hat actor.
That read held up. Zach later shared an on-chain note sent by the bot's operator, addressed to the Rho team:
"Hello RHO team, our MEV bot have profited from your price oracle misconfiguration. We understand that the funds belong to users and are willing to fully return. But first we would like you to admit that it was not an exploit or a hack, but a misconfiguration on your end. Also, please provide what are you going to do to prevent it from happening again?"
The operator followed through, and the full amount was sent back shortly afterward. Rho Markets subsequently confirmed that the matter was closed with no net loss of user funds, and that it was in the process of restoring balances to the borrow pools.
The team laid out a three-part recovery plan:
- Identify the accounts that had supplied funds while the oracle was malfunctioning.
- Top up the USDC, USDT, and wstETH pools to make affected users whole.
- Restore borrowing and transfer functions under tightened security procedures.

Notably, an earlier security audit had already flagged possible weak points in the oracle setup — but the root cause here was a human deployment error rather than a flaw in the underlying code.
The episode reopened a broader argument about decentralization on Layer 2s. Since Rho's mishap led Scroll to pause its chain, security researcher Sudo (pcaversaccio) argued that L2 networks marketing themselves as permissionless and censorship-resistant are often just courting venture capital, while Ethereum's base layer remains the more genuinely decentralized option.
The dilemma facing L2 operators, in this view, is a real one: intervene to protect user funds and invite accusations of centralization, or hold to permissionless principles and leave users exposed. As sequencers and provers on these networks stay concentrated in a handful of hands, concerns are mounting that operators themselves could become single points of failure — both technically and legally.
Get new scam files the moment we publish them — usually 2–3 emails a week.